Subject: Re: NetBSD 1.5.2 default configuration
To: None <xs@kittenz.org>
From: Wojciech Bojdol <wojboj@htcon.pl>
List: tech-security
Date: 02/03/2002 16:36:33
On Sun, Feb 03, 2002 at 03:10:06PM +0000, xs@kittenz.org wrote:
> It's more open and "friendly".
In my opinion it's too insecure.
But - for people like me is good small script that will change the default
for my needs.
> It depends on the medium I store them on.
It's between 0.01$ and 1$ ? :)
> How much does it cost to type
> gzip -d wtmp.xx.gz; last -f wtmp.xx ? :)
It cost me time. On old machines - could be to much of time.
last with support of pipe could be good, but now the best is to not compress
that files.
> > If you want to give users right to change their crontabs via www
> > you have to do some script suid root.
>
> Not really, put the output from crontab -l into a textarea, and then when
> the user clicks "save" pipe the current contents of that textarea into
> crontab -. Assuming whatever user executes the (nonsuid) script has
> rights to run crontab, which it would if you used a system like apache's
> suEXEC.
In my oppinion it's insecure model.
Good, tested suid script/program would be better for that.
> Or as a users login shell.
That users need to run pppd as root ?
--
Wojciech Bojdoł
High-Tech Consulting